CVE-2022-30970: XSS
Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete String parameter names in an unsafe manner from Javascript embedded in view definitions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30970?
CVE-2022-30970 has been classified as a medium severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
How do I fix CVE-2022-30970?
To remediate CVE-2022-30970, users should upgrade the Jenkins Autocomplete Parameter Plugin to version 1.2 or later.
What types of attacks are possible with CVE-2022-30970?
CVE-2022-30970 allows attackers to exploit stored XSS vulnerabilities, potentially leading to unauthorized access and data manipulation.
Who is affected by CVE-2022-30970?
Users of Jenkins Autocomplete Parameter Plugin versions 1.1 and earlier are at risk from CVE-2022-30970.
What software versions are impacted by CVE-2022-30970?
CVE-2022-30970 affects Jenkins Autocomplete Parameter Plugin versions up to and including 1.1.